How provably fair works, and how to check a bet yourself
Provably fair lets you check that a casino did not change a result after you bet. Here is how the seeds and hashes work, how to check a bet, and what the check leaves out.
By Alexander Jeff Lange
- Level
- Intermediate
Key takeaways
- Provably fair proves one thing: the casino fixed its secret seed before you bet and did not change it afterwards.
- Each result is made from three inputs: the casino's server seed, your client seed and a nonce that counts your bets.
- To check a bet, save the server seed hash before you play. Compare it with the seed the casino reveals when you switch seeds.
- The check says nothing about the house edge, whether you will be paid, or whether the casino can cover what it owes.
- A provably fair label on a casino does not cover slots and live games from outside providers.
When you bet at an online casino, you cannot see the dice. The casino's computer works out the result and shows you a number. Provably fair is a method that lets you check, after the bet, that the casino did not change that number once it knew what you had staked.
One thing first: a game can pass every check in this guide and still cost you money. It keeps its house edge, so you lose on average.
What problem does provably fair solve?
In a real casino you can watch the wheel spin. Online, the result is made on a server you cannot see. A dishonest casino could wait for your bet and then pick a result that makes you lose. You would have no way to tell.
Provably fair closes that gap with two ideas.
- Both sides add something to the result. The casino brings one secret value and you bring another. Neither side can set the result alone.
- The casino locks in its value before you bet. It cannot show you the value itself, because then you could work out the result in advance. So it shows you a fingerprint of the value, and reveals the value later.
Think of a sealed envelope. The casino writes down a number, seals it and hands you the envelope. You then say your own number. The result is made from both. Afterwards you open the envelope and check the number inside.
What are the server seed, client seed and nonce?
Three inputs go into every bet: the server seed, the client seed and the nonce.
| Part | Who sets it | When you can see it | What it is for |
|---|---|---|---|
| Server seed | The casino | Only its hash before you bet. The seed itself after you switch to a new one. | The casino's secret share of the result |
| Client seed | You. The casino fills in a starting value that you can change. | At any time | Your share, so the casino cannot plan the result alone |
| Nonce | It counts up by itself | At any time | Makes each bet different while the seeds stay the same |
The two seeds are strings of characters. The nonce is a counter. It goes up by one with each bet you place under the same pair of seeds. Without it, every bet under those seeds would give the same result.
What is the hash the casino shows you before the bet?
A hash is a fingerprint of a piece of data. A common choice is SHA-256, which is a public standard and the one our tool checks. Four things about it matter here.
- Whatever you put in, you get 64 characters out, made of the digits 0-9 and the letters a-f.
- The same input always gives the same hash.
- Change one character of the input and you get a different hash.
- It is one-way. You cannot work back from the hash to the input.
This is what makes the envelope work. Before you bet, the casino shows you the hash of its server seed. That is the commitment. The casino is now tied to that seed. If it later reveals any other seed, the hash of that seed will not match the one you were shown.
The reveal comes when you switch to a new pair of seeds. The casino then shows you the old server seed in full. It cannot do this sooner, because anyone who holds the server seed can work out every result still to come under it.
Warning
A match only means something if you saw the hash before you bet. Save it outside the casino's website, or take a screenshot, before you play.
How does a seed become a dice roll or a card?
The broad steps look like this.
- The casino mixes the server seed, the client seed and the nonce with a hash function. A common tool for this is HMAC, a standard way of running a hash function with a secret key. What comes out is a long string of characters called a digest.
- It takes part of the digest and reads it as a number.
- It scales that number to what the game needs, such as a roll between 0 and 99.99, a place in a deck of cards, or a multiplier.
Once the three inputs are fixed, the result is fixed too. That is why anyone who has all three can repeat the sum.
The details are not the same everywhere. Casinos differ in the hash function they use, the order of the parts, the character placed between them, how much of the digest is used, and how the number is scaled. Each game also has its own last step. A formula that is right at one casino gives the wrong answer at another.
So the casino has to publish its method for each game. If it shows you hashes but does not say how a result is worked out from the seeds, there is nothing you can check.
Note
Games where every player shares one result, such as crash, cannot use your own client seed and nonce. They use other designs, and casinos differ. For these games, read the casino's own fairness page.
How do you check a bet yourself?
You need four things: the hash you saw before the bet, the revealed server seed, your client seed and the nonce of the bet.
- Before you bet, open the fairness or seed settings at the casino. Copy the hash of the active server seed and save it somewhere outside the casino's website.
- Change the client seed to something of your own. Do this after the hash is on your screen, not before. If the hash changes when you change the client seed, save the new one.
- Play. For the bet you want to check, write down its nonce.
- Switch to a new pair of seeds. The casino now reveals the server seed you were playing on.
- Open the provably fair verifier. Paste the revealed seed into "Server seed (revealed)" and the hash you saved into "Server seed hash (shown before the bet)".
- Read the first result, "Was the seed fixed before the bet?". "Match" means that the SHA-256 hash of the revealed seed is the hash you saved.
- Type in your client seed and the nonce. The second result shows the raw digest for that bet.
- Use the casino's published method, or its own verifier, to turn the seeds into the game result. Compare that with the result you were shown.
What the tool does
- It runs SHA-256 over the revealed server seed and compares the answer with the hash you entered. Some casinos hash the seed as plain text. Others hash the bytes that a hex seed stands for. The tool tries both and tells you which one matched.
- It runs HMAC-SHA256 with the server seed as the key. The message is your client seed, a colon and the nonce. It shows you that message and the 64-character digest.
- It works in your browser and sends nothing you type anywhere.
What the tool does not do
- It does not work out your roll, card or crash point. That last step differs for every casino and every game.
- It does not copy any casino's formula. It uses one fixed message format. If your casino builds its message another way, its digest will differ from the tool's. That alone does not mean the game was unfair.
Try it with the example
Press "Fill in the example" in the tool. The values were made up for the tool and belong to no casino.
- Server seed: 54598a9962b6a6f2553a73b0c93a84e428d05dae014ebd120ae9db42a0923a79
- Hash shown before the bet: ff54e47d3a4d5bc89541f7b15967676f1cda9065203d73fc8ffb50fc5268725a
- Client seed: degenowl
- Nonce: 1
- Message that is signed: degenowl:1
- Digest: 8e35d87c1ccdb552a08e48f165c8b324ee913ebf7543a952e242684ffe275196
The first result says "Match". Now change one character of the server seed. The first result turns to "No match", and the digest changes as well.
What if the tool says "No match"?
Check these first.
- A missing or extra character in the seed or the hash.
- The wrong hash. Once you switch seeds, the hash on screen belongs to the new seed, not to the one just revealed.
- Another way of hashing. Read the casino's own instructions.
If it still does not match, keep your saved hash and the revealed seed, and ask the casino to explain. If the casino says it uses SHA-256 and the two really do not match, the seed it revealed is not the seed it committed to.
What does provably fair not prove?
The check answers one narrow question. Here is what it leaves open.
| Question | Does the check answer it? | Where the answer comes from |
|---|---|---|
| Was the server seed swapped after I bet? | Yes, if you saved the hash first | The commitment check |
| Does my result follow from the seeds? | Only if the casino publishes its method and you run it | The published method |
| Does the game have a house edge? | No | The game's rules and its RTP |
| Will the casino pay my withdrawal? | No | Its terms, its licence and its record |
| Can the casino cover what it owes players? | No | Nothing a seed can show |
| Are slots from outside providers fair? | No | The provider's testing |
The house edge. A provably fair game still pays out less than the true odds. Fair here means "not changed after the bet". It does not mean "even". The share a game pays back is its RTP, and house edge and RTP explains how to read it.
Payouts and solvency. The check covers how one number was made. It does not show that your balance is right, that a withdrawal will be paid, or that the casino holds enough money to pay everyone. For those questions, see how to check a crypto casino is legit.
How the server seed was picked. The commitment stops the casino from changing its seed. It does not prove the seed was picked at random. If the casino could guess your client seed, it could choose a server seed that suits it. A client seed you set yourself, after the hash is shown, takes that option away.
Games from outside providers. Slots and live dealer games usually come from a separate game provider. A provably fair label on the casino does not cover them unless the game itself offers the check. Their fairness rests on the provider's random number generator and on test labs. As one example, the UK Gambling Commission requires game results to be "acceptably random", and has approved test houses check the random number generator and the RTP of games before release. Those rules bind only the casinos it licenses.
What mistakes do people make with provably fair?
Never changing the client seed
The casino gives you a starting client seed. If you keep it, you are trusting the casino for both halves of the result. Type in your own, and do it after you have seen the hash of the server seed.
Checking only after a loss
The check depends on a hash you saved before the bet. If you only think of it after losing, you have nothing of your own to compare with. A loss that passes the check is also still a loss: wins and losses come out of the same sum. Save the hash as a habit before you play, not as a reaction afterwards.
Trusting only the casino's own verifier
The casino's verifier is a page the casino wrote. When it says "verified", you are taking its word. SHA-256 is a public standard, so any independent tool gives the same hash for the same seed. Do the commitment check away from the casino's website. For the game result you do need the casino's method, so look for a written description or code that you can run somewhere else.
Questions people ask about provably fair
Does provably fair mean the game has no house edge?
No. It means the result was not changed after you bet. The game still pays less than the true odds, so you lose on average. House edge and RTP explains the numbers.
Can I check a bet while I am still playing on the same seed?
No. The server seed stays secret until you switch to a new pair of seeds.
Do I have to check every bet?
The commitment check covers a whole server seed, so one check covers every bet you placed under that seed. Working out the result of a bet is a separate step, and you repeat it for each nonce you want to check.
Are slots at a crypto casino provably fair?
Only if the slot itself offers the check. A provably fair label on the casino's own games tells you nothing about games from outside providers. Those depend on the provider's testing.
Keep reading
Guide
House edge and RTP: what the numbers really mean
RTP is the share of all bets a game pays back. House edge is the share it keeps. Here is how to turn either one into an expected loss, and why one session can look nothing like it.
Guide
How to check a crypto casino is legit before you deposit
A licence logo proves nothing by itself. How to check the licence, the company, the ID rules, the games and the terms before you send any money.